terminal-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent ingests untrusted data from external sources and performs sensitive actions based on that data.
  • Ingestion points: The agent is instructed to read "logs", "command output", "git state", and "repo files" during the 'Read the failing surface first' phase (SKILL.md).
  • Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions that might be embedded within the external files or logs being analyzed.
  • Capability inventory: The skill allows the agent to execute arbitrary terminal commands, modify the filesystem, and push changes to remote repositories (SKILL.md).
  • Sanitization: There are no documented steps for sanitizing or validating external input before it influences the agent's actions or commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — terminal-ops